Closed tender

Virtual Machine Introspection deception demonstrator Phase 2

Details

Published
12 July 2022
Submission
26 July 2022

Tender description

Summary of the work The approach will prove distributed control of VMI deception activities, further develop the hypervisor to utilize multiple CPU cores and enable multiple deception concepts to be utilized on individual VMs. The approach will develop new deception concepts targeted at deceiving/disrupting Cobalt Strike activity and mature pre-existing deception concepts. Expected Contract Length 7-8 Months Latest start date Thursday 1 September 2022 Why the Work is Being Done DSTL wants to develop generic cyber detect/respond concepts that can be applied to military challenges. Virtual Machine Introspection (VMI) allows for the monitoring of the runtime state of application generated system level instructions in virtual environments. Using VMI it should be possible to manipulate these low level requests in order to feed intentionally erroneous data back to the source, deceiving the adversary utilizing it. By utilizing standardized command and control language it should be possible to automate the orchestration of this this deception activity with other defensive tooling. Problem to Be Solved Current cyber deception approaches typically rely on deceiving adversaries either before they gain access to internal networks and/or during the lateral movement phases of an intrusion. When deception is utilized, it is typically at the network level – once a malicious actor gains access to an individual host, current deception measures are often limited. What measures are available often contaminate hosts with tell-tale signs of their presence (logs, suspicious processes, or inconsistent decoy data which stands out), or may be bypassed through modified Tools, Techniques and Procedures (TTPs). Who Are the Users As a Cyber Security Researcher, I need to determine the viability of orchestrated VMI-based deception. I need software development resourcing to further develop a pre-existing custom Xen hypervisor targeting virtualized Windows hosts. This includes extending the hypervisor to facilitate execution of multiple deception concepts on individual VMs. I need the hypervisor to use multiple CPU cores where possible and be able to orchestrate this deception activity using OpenC2.I need additional deception concepts that are able to directly affect Cobalt Strike adversary activity. I need pre-existing deception concepts to be further developed to make it harder for adversaries to bypass them. Work Already Done The previously funded development phase led to the creation of a custom Xen-based Virtual Machine hypervisor targeting Windows 10 VMs. This solution utilized the LibVMI software library and DrakVUF to create a set of basic Cyber deception concepts. This implementation included a web front end for logging and administration of individual concepts against target VMs and an OpenC2 API for remote orchestration of effects. This development was focused on testing the fundamental concept of using VMI for deception. This codebase will be provided to the successful bidder to form the basis for the proposed further work. Existing Team The supplier will be working with one or more dedicated technical partner(s) from DSTL for day to day interaction. A small team from the Authority will contribute to and review work carried out under this task where appropriate. This team will act as hosts, when or should the need to work on or demonstrate the concepts on our site arises. This team operates out of their own laboratory space which is equipped to support software development and deployment. The supplier may be expected to reach out to international standards bodies to understand how to utilize or enhance existing standards. Current Phase Alpha Skills & Experience • Demonstrate experience creating software using Python 3 and/or C to run on Debian-based Linux operating systems (>= Ubuntu 18.04 LTS) without reliance on closed-source, proprietary, software dependencies. • Demonstrate, with evidence the ability to conduct agile software development in-house, without support from subcontractors. • Demonstrate with evidence the ability to continue and evolve software development from a complex inherited and/or Open Source codebases. • Demonstrate with evidence the ability to deliver without authority funded capability enhancements (for example, procurement of additional ICT to support development activities). • Demonstrate experience developing cyber security or system management software (preferably for high threat and government organisations). • Demonstrate, with evidence, the ability to produce appropriate levels of documentation, and conduct verification and validation of software. • Demonstrate experience using the Git-Source-Code-Management(SCM)system and broader collaborative development tool suites.Provide examples of how you've provided customers with access to developmental&release versions of software-source-code,and engaged them in the development process. Nice to Haves • Demonstrate, with evidence, experience utilising the LibVMI, DrakVUF, and/or other VMI software libraries in the development of cyber security tooling. • Demonstrate, with evidence, experience of working with, monitoring and/or manipulating systemcalls on Windows-based operating systems. • Demonstrate, with evidence, working knowledge of x86 cpu instruction sets and manipulating system memory. • Indicate, with evidence of prior work, the ability to adhere to appropriate coding standard(s) for the development of software • Demonstrate, with evidence, experience utilising VMI for the creation of Deception Effects Work Location We would expect the majority of the work to be conducted at the suppliers own address, but there maybe times when both formal meetings and development work will take place at our Salisbury (Wiltshire) site. Working Arrangments To ensure that the demonstrator can be utilized to facilitate human testing, the project will utilize an iterative and incremental approach to delivery. The supplier must adopt an Agile system engineering approach (e.g. Scrum) and work closely with the Authority throughout the development process to realize the project’s aims. It is expected that this work will require significant dialogue between the Authority and the supplier throughout the contract period; the Authority will make staff available to support this. Security Clearance Able to handle OFFICIAL SENSITIVE material only. Research Worker forms will need to be completed for everyone working on this contract to work at Official and Official-Sensitive. No. of Suppliers to Evaluate 5 Proposal Criteria • The proposed technical solution offered by the supplier in terms of how closely it addresses the problem as described above • The technical measures/steps taken by the supplier to ensure the proposed approach addresses all the stated technical needs of the users. • The overall approach and methodology proposed to achieve the solution. • The proposed additional deception concepts utilising VMI and targeted at hindering Cobalt Strike activity. • The project management plan provided by the supplier. This should include (but not be limited to an initial backlog, GFA/GFI requirements, any commercial aspects and the suppliers Software Development Capability. • The timeframes for the work (deliverables and other milestones dates as appropriate). These timeframes should be included within the project plan using a Gantt chart and/or other suitable visualisation(s). • Detail and explain identified risks and dependencies. Provide details of offered approaches to manage these risks via a risk assessment with mitigations • Value for money Cultural Fit Criteria • Demonstrate consistent cultural commitment to agile software development practices. • Demonstrate with evidence that they are able to articulate their work to clients with low technical expertise. • Demonstrate with evidence an ability to collaboratively work with both a customer and other suppliers/relent 3rd parties on a piece of work. • Demonstrate with evidence being transparent and collaborative when making decisions. • Demonstrate with evidence of sharing knowledge and experience with other team members. • Demonstrate with evidence an ability to successfully solve deliver and solve problems within the UK Defence landscape. Payment Approach Fixed price Evaluation Weighting Technical competence 70% Cultural fit 10% Price 20% Questions from Suppliers 1. Was there a supplier for Phase 1 of this work? If so could you please confirm who that was? Yes. All details relating to phase 1 can be found here. https://www.contractsfinder.service.gov.uk/Notice/e08dc0bb-e482-46e9-8dc6-715e296fc6e4

Timeline

  1. Completed: Tender published12 July 2022
    Current notice
  2. Completed: Submission date26 July 2022

About the buyer

Defence Science & Technology Laboratory is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to Virtual Machine Introspection deception demonstrator Phase 2, ranked by notice volume.

View all topics
TopicCountValue
  1. 5,186
    £736.1bn
  2. 11,699
    £1.1tn
  3. 11,175
    £1.0tn
  4. 26,970
    £1.7tn
  5. 4,088
    £269.5bn
  6. 4,068
    £249.4bn

Related buyers

Buyers similar to Defence Science & Technology Laboratory.

View all buyers

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.